CVE-2026-41183 MEDIUM

CVE-2026-41183: FreeScout allows non-folder conversation queries to disclose assigned-only hidden conversations

Vendor Freescout-Help-Desk
Product freescout
Weakness CWE-200 · Info exposure
Published April 21, 2026
Last update April 21, 2026

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the assigned-only restriction is applied to direct conversation view and folder queries, but not to non-folder query builders. Global search and the AJAX filter path still reveal conversations that should be hidden. Version 1.8.215 fixes the vulnerability.

Key dates

02Disclosure timeline

April 21, 2026 CVE published
April 21, 2026 Record updated